Security Basics mailing list archives

Re: Root account desactivated


From: Michael Gale <michael () bluesuperman com>
Date: Thu, 11 Mar 2004 19:03:14 -0700

Organization: Bluesuperman.com
X-Mailer: Sylpheed version 0.9.8claws (GTK+ 1.2.10; i686-pc-linux-gnu)
Mime-Version: 1.0
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


HAHHAHAHAHA .....

Take a slackware CD, boot from it. You will end up a command prompt. Now
type the following commands as shown, if it fails use a Win2k CD and
follow the on screen instruction.

root <ENTER> =3D logs you in as root
mount /dev/hda2 /mnt =3D replace /dev/hda2 with the drive and partition
that the RH /etc directory is on. It not sure you can try
/dev/hda1,/dev/hda2,/dev/hda3 and so on ....

cd /mnt/etc
vi passwd

vi commands:
i =3D allows you to insert text
x =3D like delete in command mode
ESC =3D enter command mode
q =3D exit
q! =3D exit a modified file
wq =3D exit and save a modified file

Once you are done, unmount the drive:
umount /mnt
reboot

That should fix the problem, now change the root password.

Michael.




On Thu, 11 Mar 2004 17:50:08 -0500 (EST)
sil <jesus () resurrected us> wrote:

=20
=20
If you have sudo on the machine you can try doing something like
=20
sudo sed 's/\/sbin/\/nologin/\/bin\/bash/g' /etc/passwd >>
/tmp/passwd|\ mv /tmp/passwd /etc/passwd
=20
=20
=20
-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D-=
=3D-=3D-=3D-=3D-=3D-=3D-=3D-=3D
"The most tyrannical of governments are those which make
crimes of  opinions, for everyone has an inalienable
right to his thoughts." -- Benedict Spinoza
=20
=20
//sil
=20
http://www.kungfunix.net   http://www.politrix.org
http://www.infiltrated.net http://bush.shafted.us
=20
On Thu, 11 Mar 2004, MARTIN M. B=E9noni wrote:
=20
Hi community!

I have a really stupid trouble: on a Redhat 9.0, the line matching
the root account in the file /etc/passwd has been changed from
".../bin/bash" to".../sbin/nologin". We have the root password, but
when performing a "su" command, the system replies that the account
is not currently available.

So the question is: how from an user's account and knowing the
root's password but having the root account disabled can we
reactivate this root's account?

Any suggestion would be appreciated, I do not want to reinstall the
box :(

Thanks a lot in advance!

_________________________________________________________________
MSN 8 with e-mail virus protection service: 2 months FREE*
http://join.msn.com/?page=3Dfeatures/virus


-------------------------------------------------------------------
-------- Ethical Hacking at the InfoSec Institute. Mention this ad
and get $545 off any course! All of our class sizes are guaranteed
to be 10 students or less to facilitate one-on-one interaction with
one of our expert instructors. Attend a course taught by an expert
instructor with years of in-the-field pen testing experience in our
state of the art hacking lab. Master the skills of an Ethical Hacker
to better assess the security of your organization. Visit us at:
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
-------------------------------------------------------------------
---------


=20
---------------------------------------------------------------------
------ Ethical Hacking at the InfoSec Institute. Mention this ad and
get $545 off any course! All of our class sizes are guaranteed to be
10 students or less to facilitate one-on-one interaction with one of
our expert instructors. Attend a course taught by an expert instructor
with years of in-the-field pen testing experience in our state of the
art hacking lab. Master the skills of an Ethical Hacker to better
assess the security of your organization. Visit us at:=20
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
---------------------------------------------------------------------
-------
=20


--=20
Hand over the Slackware CD's and back AWAY from the computer, your geek
rights have been revoked !!!

Michael Gale
Slackware user :)
Bluesuperman.com=20

---------------------------------------------------------------------------
Ethical Hacking at the InfoSec Institute. Mention this ad and get $545 off 
any course! All of our class sizes are guaranteed to be 10 students or less 
to facilitate one-on-one interaction with one of our expert instructors. 
Attend a course taught by an expert instructor with years of in-the-field 
pen testing experience in our state of the art hacking lab. Master the skills 
of an Ethical Hacker to better assess the security of your organization. 
Visit us at: 
http://www.infosecinstitute.com/courses/ethical_hacking_training.html
----------------------------------------------------------------------------


Current thread: